Definition · Known Vulnerabilities (CVEs)
What is Exploit?
An exploit is the practical means of turning a vulnerability into an effect. The vulnerability is the flaw; the exploit is what an attacker sends, types, or runs to abuse it. A single vulnerability can have many exploits of differing reliability, and some vulnerabilities are never successfully exploited at all.
Classes of exploit
- Remote exploits operate over the network against a listening service, and are the class that matters most for internet-facing assets
- Local exploits require existing access to the host, typically used for privilege escalation after an initial foothold
- Client-side exploits target software that processes attacker-supplied content, such as a browser or document reader
From disclosure to exploitation
Published vulnerabilities often follow a recognisable path: an advisory appears, a proof-of-concept exploit demonstrates that the flaw is real, and a more reliable weaponised version follows. Not every step happens for every CVE, which is why exploit availability is a distinct input to prioritisation rather than something a severity score already captures.
Why it matters for external exposure
An exploitable service that is reachable from the internet needs no phishing, no insider, and no lateral movement to be useful to an attacker — it is directly addressable. That makes exposure a multiplier on exploitability: the same flaw on an internal-only host and on a public one are not the same risk.
Related concepts
CVSS rates theoretical severity, EPSS estimates the probability of exploitation, and the KEV catalogue records where exploitation has actually been observed. Together with zero-day awareness they inform vulnerability management decisions about what to fix first.